
highCyber Attacks
Mustang Panda Deploys Signed Windows Rootkit with Updated CoolClient Backdoor
Kaspersky reports that the threat actor known as Mustang Panda (aka HoneyMyte) has updated its CoolClient backdoor with a signed Windows kernel-mode rootkit. The rootkit is capable of hiding malicious processes, files, registry objects, and C2 network information from detection. Victims have been identified in Myanmar, Mongolia, and Pakistan, though the full scope and infection vectors remain under investigation.
The Hacker News1 min read